Analytics
Which Crypto Is Quantum Resistant in 2026?
Which crypto is quantum resistant? We map twelve chains racing to beat Q-Day โ approach, build status and migration timeline โ and why the fix trails the threat.
Key Takeaways
- No quantum computer can break Bitcoin today. Cracking its keys needs 1,200 to 1,450 logical qubits, far beyond IBM's roughly 200-qubit 2029 target.
- The big chains are migrating right now. Bitcoin, Ethereum, Solana, XRP, Algorand and NEAR all published post-quantum plans between April and July 2026.
- NEAR already switched quantum-safe signing on. It went live on mainnet on July 20, 2026; Algorand and Aptos rate as the most ready.
- About 6.9 million BTC have exposed public keys. Roughly 1.1 million of those are Satoshi's coins, spread across about 22,000 wallets.
- The threat arrives faster than the fix. Q-Day looks likely around 2030 to 2033, but a full chain migration takes close to a decade.
- 1. What Is Quantum-Resistant Crypto โ and Is the Threat Real Yet?
- 2. Which Crypto Projects Are Actually Building Quantum Resistance?
- 3. Is Bitcoin Quantum Resistant? BIP-360, BIP-361 and the ~6.9M Vulnerable BTC
- 4. Is Ethereum Quantum Resistant? The Foundation's Post-Quantum Roadmap
- 5. How Solana, Algorand, XRP, NEAR, TRON and Zcash Are Migrating
- 6. Quantum-Resistant Coins to Watch in 2026
- 7. How to Protect Your Crypto From Quantum Computers Now
- 8. Q-Day Timeline: Why Migration Is Slower Than the Threat
- 9. Where to Research and Track Quantum-Resistant Coins on DropsTab
What Is Quantum-Resistant Crypto โ and Is the Threat Real Yet?
Quantum-resistant crypto means blockchains whose signatures survive a large quantum computer. Shor's algorithm can break the ECDSA keys that secure Bitcoin and Ethereum. Grover's algorithm only halves the strength of SHA-256 hashing, so mining and proof-of-work stay safe. No machine today reaches the break threshold.
The exposure sits in the signatures, not the hashing. Shor's algorithm recovers a private key from an exposed public key. Grover's algorithm gives only a quadratic speedup on SHA-256, cutting 256-bit security to about 128-bit. That still holds.
The threshold is now measured. Google Quantum AI reported on March 30, 2026 that breaking a 256-bit elliptic-curve key needs 1,200 to 1,450 logical qubits, under 500,000 physical qubits, and about nine minutes of runtime.
That was a roughly 10x cut in resources, which Ethereum researcher Justin Drake called a "technical bombshell." As Drake put it, "a fast superconducting computer would recover private keys in minutes."
The hardware is not close. IBM's Starling chip, due in 2029, targets around 200 logical qubits. In the Project Eleven Q-Day Prize (April 2026), the best public result broke a 15-bit key, 512 times the prior record, yet still tiny against 256 bits. The gap is "engineering, not a fundamental problem." That is the honest read: real, but not here yet.

That divide runs through the experts themselves. At Bitcoin 2026, a Galaxy-moderated panel โ with BIP-360's Hunter Beast, Project Eleven's Alex Pruden and skeptics James O'Beirne and Brandon Black โ put the same question on stage and closed split: from Black's flat "not at all real" to Pruden's "one-percent chance, and we should act." The panel also picked apart the 15-bit result as classical pre-computation dressed in a quantum wrapper โ the same caution this piece takes. The full Bitcoin Magazine debate is below, moderated by Galaxy's Alex Thorn; the player carries several audio-track languages, so pick whichever reads easiest.
Which Crypto Projects Are Actually Building Quantum Resistance?
Twelve major chains are building quantum resistance through three approaches. Bitcoin, Ethereum, XRP and NEAR migrate their signatures to new post-quantum schemes. Starknet resists by architecture, since STARK proofs are hash-based. QRL has run post-quantum from genesis. Most target full protection between 2027 and the early 2030s.
Coinbase's Advisory Council (April 21, 2026) ranked readiness in three tiers: Aptos and Algorand as leaders, Solana and the Ethereum L2s as moderate, and Bitcoin, Ethereum and Sui as early. The table below maps every chain's approach, scheme, status and timeline.
| Project | Post-quantum approach | NIST scheme | Build status | Migration timeline | Supply / category |
|---|---|---|---|---|---|
| Bitcoin | BIP-360 quantum-safe output + BIP-361 legacy-signature sunset | ML-DSA (FIPS 204); BIP-361 scheme-agnostic | BIP-360 Draft, merged 2026-02-11; P2MR live on signet 2025-09-10 | Phase A ~3yr, Phase B ~5yr flag-day, Phase C optional ZK recovery | 21M cap, ~20.06M mined ยท Cryptocurrency |
| Ethereum | "Lean Ethereum": BLSโhash-based sigs, recursive STARKs, QR blobs | Hash-based (XMSS family); STARKs (non-NIST) | Research/roadmap; "third major iteration" | 3โ4yr scope; full PQ early-to-mid 2030s (Drake cites 2029 start) | uncapped, ~120.7M ยท Blockchain |
| Solana | Falcon sigs (Anza + Firedancer); Winternitz Vault | FN-DSA/Falcon (FIPS 206 pending); Winternitz hash-based | Falcon impls built; Vault live 2+ yrs, opt-in | New wallets first; "years away, migration ready" | uncapped, ~631M ยท Blockchain |
| Algorand | State Proofs on Falcon (since 2022) โ native Falcon-1024 accounts | FN-DSA/Falcon (FIPS 206 pending) | Executed a QR mainnet transaction | Native Falcon-1024 Q3 2026 โ broad resilience end-2027 | 10B cap, fully diluted ยท Blockchain |
| Aptos | AIP-137 account-level SLH-DSA; key rotation, no asset move | SLH-DSA (FIPS 205) | Proposed Dec 2025; opt-in | Opt-in, no forced date; Coinbase co-Leader | 2.1B cap, ~1.21B ยท Blockchain |
| XRP Ledger | 4-phase: ZK proofs โ NIST test โ parallel PQ+ECDSA โ amendment | NIST-standardized (set TBD) | Phase 2 testing H1 2026; Devnet H2 2026 | Full production PQ by 2028 | 100B cap, ~99.99B ยท Crypto Treasury Assets |
| NEAR | Multi-key accounts: add ML-DSA key, no asset move, no hard fork | ML-DSA-65 (FIPS 204) | LIVE ON MAINNET via v2.13, 2026-07-20 | Mainnet live; opt-in adoption ongoing | uncapped, ~1.30B ยท Blockchain |
| TRON | "NIST post-quantum signatures" โ scheme unspecified | Unspecified | Nile testnet build; "first" claim refuted | Testnet Q2 โ mainnet Q3 2026 (planned) | uncapped, ~94.9B ยท Blockchain |
| Zcash | Quantum-recoverable wallets โ full PQC; algorithm undisclosed | Not disclosed | Recoverable wallets ~June 2026 | Full PQ 12โ18 months (~2027) | 21M cap, ~16.8M ยท Privacy Coin |
| Starknet | Resistant by architecture (STARK = hash-based); Falcon-512 wallet | Falcon (FIPS 206 pending); STARKs non-NIST | S2morrow wallet live April 2026 | Phase 1 new activity โ Phase 2 legacy; no hard endpoint | uncapped, 10B ยท Layer-2 |
| Optimism | ECDSA EOA โ smart accounts with PQ sigs (EIP-7702) | PQ scheme (unspecified) | "Post-Quantum Roadmap for the Superchain" published | 10-yr transition; ECDSA sunset January 2036 | 4.29B cap, fully diluted ยท Layer-2 |
| QRL | PQ-native from genesis (XMSS, hash-based, reusable addresses) | XMSS (NIST SP 800-208) | Live since June 2018; Halborn audit March 2026 (0 crypto vulns) | Operational from inception โ no migration | 105M cap, ~79.6M ยท Web 3.0 |
| Supply and category: DropsTab data, as of 2026-07-30. | |||||
QRL is one of several post-quantum-native chains. IOTA (Winternitz OTS), Cellframe, Abelian (lattice, 2018) and QANplatform (QANX, Dilithium) also run PQ from the protocol layer.

The money, though, sits with the giants. To size that, DropsTab Research assembled the migrating chains into one custom tab โ market cap, one-year and year-to-date performance side by side. One pattern dominates.
| Asset | Market Cap | Category | 1Y % | YTD % |
|---|---|---|---|---|
| BTC | ~$1.30T | Cryptocurrency | โ46% | โ27% |
| ETH | ~$231B | Blockchain | โ50% | โ36% |
| XRP | ~$68B | Crypto Treasury Assets | โ65% | โ42% |
| SOL | ~$43B | Blockchain | โ59% | โ41% |
| TRX | ~$31B | Blockchain | โ0.5% | +14% |
| ZEC | ~$8.0B | Privacy Coin | +1120% | โ8% |
| NEAR | ~$2.2B | Blockchain | โ39% | +7% |
| ALGO | ~$703M | Blockchain | โ70% | โ30% |
| APT | ~$484M | Blockchain | โ87% | โ66% |
| OP | ~$202M | Layer-2 | โ87% | โ67% |
| STRK | ~$173M | Blockchain | โ79% | โ67% |
| Source: DropsTab custom tab, as of 2026-07-30. | ||||

Bitcoin and Ethereum together hold about 91% of the basket's market value โ so most of the money moving to post-quantum security rides on just two roadmaps. DropsTab Research, as of 2026-07-30.
Is Bitcoin Quantum Resistant? BIP-360, BIP-361 and the ~6.9M Vulnerable BTC
Bitcoin is not quantum resistant yet. It signs transactions with ECDSA and Schnorr, both breakable by Shor's algorithm. Two proposals, BIP-360 and BIP-361, sit in draft. About 6.9 million BTC rest in addresses with exposed public keys, a standing target for any future quantum attacker.
BIP-360, authored by Hunter Beast, adds a quantum-safe output type with Dilithium/ML-DSA opcodes. It is in Draft, merged into the bitcoin/bips repo on February 11, 2026, and its first transaction ran on signet on September 10, 2025.
BIP-361, led by Jameson Lopp, is scheme-agnostic and phased. Phase A blocks sends to vulnerable addresses over about three years. Phase B is a roughly five-year flag-day that invalidates ECDSA and Schnorr signatures, freezing legacy coins. Phase C is an optional zero-knowledge recovery fork. The proposal notes that over 34% of BTC supply sits in exposed addresses. Its authors frame it as "defensive, not offensive."
Two stopgaps exist, both temporary. QSB (StarkWare, April 2026) offers a RIPEMD-160 hash-to-signature scheme with about 118-bit resistance at $75โ150 per transaction, still in development. Lightning Labs proposed an Emergency Backup Access system using zk-STARK ownership proofs.
The vulnerable coins fall into nested layers, not a conflict. About 6.9 million BTC sit in key-exposed addresses (Coinbase). Within that, roughly 1.7 million rest in the oldest P2PK outputs. Within that, about 1.1 million are attributed to Satoshi, spread across roughly 22,000 wallets of 50 BTC each โ which Galaxy's Alex Thorn calls "limited and long-term." CoinShares' separate ~10,200 BTC "market-disruption" figure measures a different question.
Institutions moved too. On July 23, 2026, nine firms โ Anchorage, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy and Strategy โ launched the Bitcoin Security Consortium with ~$15 million pledged over three years.
Coinbase framed it plainly: "Quantum computing is coming. Crypto needs to be ready." The group finances research; it does not develop the protocol or take positions. A slow, funded, multi-year effort is itself a signal that the threat is not imminent.
Is Ethereum Quantum Resistant? The Foundation's Post-Quantum Roadmap
Ethereum is not quantum resistant yet. Its BLS validator signatures and KZG commitments rely on elliptic curves that Shor's algorithm can break. The Foundation's "Lean Ethereum" plan replaces them with hash-based signatures and recursive STARK proofs. Justin Drake cites a 2029 start, with full migration in the early-to-mid 2030s.
The weak points are specific. BLS validator-voting signatures and KZG commitments in the data-availability layer are elliptic-curve based and must be swapped. SNARKs are elliptic and vulnerable; STARKs are hash-based and resistant. That distinction drives the whole redesign.
Vitalik Buterin laid out "Lean Ethereum" at the Berlin researcher meeting on July 4โ5, 2026. Quantum-resistant blobs are flagged "urgent." Validator signatures move from BLS to hash-based leanXMSS. Recursive STARK proofs replace transaction re-execution. He framed it as Ethereum's "third major iteration," comparable to The Merge, with a three-to-four-year scope and the H-star fork as the last major update before the switch.
The timeline carries two figures, and both matter. Drake cites a 2029 target, which raises his odds of a code-breaking machine before 2030 to about 20%. The full Lean Ethereum transition is framed early-to-mid 2030s. The 2029 date most likely marks the migration start and blob work, not the complete switch.
How Solana, Algorand, XRP, NEAR, TRON and Zcash Are Migrating
Solana, Algorand, XRP, NEAR, TRON and Zcash each follow their own path. NEAR already runs quantum-safe signing on mainnet. Algorand ships native Falcon-1024 accounts from Q3 2026. XRP targets full protection by 2028. TRON announced a plan but named no scheme or firm date. Zcash has not disclosed its algorithm.
Solana picked Falcon independently across the Anza and Firedancer teams. Blueshift's opt-in Winternitz Vault has run for over two years and is cited by Google Quantum AI. New wallets migrate first. SOL's price still tracks Ethereum closely โ see how SOL and ETH correlate.
Algorand has run State Proofs on Falcon since 2022. It advances to native Falcon-1024 accounts from Q3 2026, hybrid classical-plus-PQ accounts, and broad resilience by end-2027. It has already executed a quantum-resistant mainnet transaction.
XRP Ledger follows Ripple's four-phase plan: zero-knowledge ownership proofs, NIST-algorithm testing with Project Eleven, parallel PQ-plus-ECDSA on Devnet, then full migration by 2028.
NEAR is the standout. Its multi-key accounts let a user add an ML-DSA-65 key in one on-chain transaction, with no asset move and no hard fork. Quantum-safe signing went live on mainnet via v2.13 on July 20, 2026.
The team calls NEAR "one of the first blockchains with a NIST-approved post-quantum signature scheme in production."
TRON announced "NIST post-quantum signatures" in April 2026 with a Nile testnet build, but named no scheme and no firm date. Its claim to be the "first major public blockchain to deploy" PQC is refuted: NEAR's mainnet launch, Algorand's Falcon transactions and QRL (PQ-native since 2018) all predate it.
Zcash targets quantum-recoverable wallets around June 2026 and full PQC in 12โ18 months. It has not disclosed the algorithm.
Quantum-Resistant Coins to Watch in 2026
- QRL โ post-quantum-native since June 2018, using XMSS (NIST SP 800-208). Supply is 105M capped, about 79.6M in circulation. A March 2026 Halborn audit found zero cryptographic vulnerabilities.
- Algorand (ALGO) โ native Falcon-1024 accounts from Q3 2026, broad resilience targeted by end-2027, on a 10B fully-diluted supply.
- Aptos (APT) โ Coinbase-rated co-leader, opt-in SLH-DSA (FIPS 205), with key rotation that does not move assets.
- NEAR โ mainnet quantum-safe signing live since July 20, 2026, using ML-DSA-65.
- Also PQ-native at the protocol layer: IOTA (Winternitz OTS), Cellframe, Abelian (lattice, since 2018), and QANplatform (QANX, Dilithium, EVM-compatible).
How to Protect Your Crypto From Quantum Computers Now
Your exposure begins the moment your public key appears on-chain. To lower the risk, avoid reusing addresses and prefer address types that hide the key until you spend. On Bitcoin, P2PKH and P2WPKH hide the key; P2PK and Taproot reveal it. Smart-contract wallets add post-quantum options.

The mechanics differ by chain. On Bitcoin, P2PKH, P2WPKH and P2WSH keep the public key hidden until the first spend, while P2PK and Taproot expose it right away. On Ethereum, the key stays hidden until the first outgoing transfer. On Solana, the public key is the account address and cannot be hidden.
A few practical steps help now. Avoid address reuse. Prefer key-hiding scripts. Where available, use ERC-4337 smart wallets that support post-quantum signatures. Multisig raises the attacker's cost, though only partially. Do not share your extended public key.
Custody adds its own risk. Balances on exchanges, and wrapped assets like WBTC, inherit the custodian's key exposure. Two attack shapes matter: a slow attack on already-exposed keys plays out over weeks, while a fast attack โ interception during migration, MEV, or harvest-now-decrypt-later โ resolves in minutes. Validator keys, bridge keys and low-threshold multisig are the prime system targets.
Q-Day Timeline: Why Migration Is Slower Than the Threat
The break threshold sits years away, yet a coordinated chain migration takes close to a decade. That gap is the reason chains move now. Q-Day estimates cluster between 2030 and 2033, though some run out to 2042. Government and infrastructure deadlines land on the same 2030s horizon.
| Source | Q-Day / migration estimate |
|---|---|
| Justin Drake (Ethereum) | 50% before 2032 ยท 10% before 2030 |
| Project Eleven | earliest 2030 ยท base 2033 ยท latest 2042 |
| Circle | most chains threatened ~2030 |
| ARK Invest | mid-2030s (Bitcoin) |
| Ethereum Foundation | early-to-mid 2030s |
| Adam Back | ~a decade to migrate after upgrade |

The skeptics have a point.
Michael Saylor calls quantum risk "substantially overestimated."
CoinShares puts real market-disruption risk at about 10,200 BTC.
Alex Thorn frames Satoshi's coins as "limited and long-term."
Tim Draper adds a systems view: "Quantum will crack the banks long before it touches the blockchainโฆ the full node operators can roll back to the last secure block. The network survives."
The alarmists attack the fix, not the threat. Charles Hoskinson calls BIP-361's recovery phase "a lie," warning that pre-2013 coins are unrecoverable without a seed and "will be stolen in the 2030s." Critics call the freeze "authoritarian and confiscatory." The debate is real and unresolved.
The wider world sits on the same clock. US Executive Order 14409 (June 22, 2026) sets federal post-quantum deadlines of December 31, 2030 for key establishment and December 31, 2031 for signatures. NIST recommends completion by 2035. Cloudflare targets 2029 for its infrastructure. This looks like a coordinated multi-year migration, not a fire drill.
Markets have not priced any of it โ so DropsTab Research ran the experiment. Our editorial team built one public portfolio: an equal-weight basket of all twelve quantum-migrating chains, each position opened at its price on January 1, 2026 and held as a fixed reference point. It is research, not a trade โ nothing has been sold, so this measures the market's verdict, not ours. What it found is blunt.
According to DropsTab Research, the twelve-chain quantum basket sat about 36% down year-to-date, versus Bitcoin's 26% โ being furthest along earned no premium. The purest play fared worst of all: QRL, post-quantum-native since 2018, is the single steepest loser at โ72%. The Coinbase-rated leaders also lagged โ ALGO โ28% and APT โ66% โ alongside L2s OP โ67% and STRK โ68%. DropsTab Research, as of 2026-07-31.

The green names reward a closer look. Only NEAR (+11%) and TRON (+15%) closed the year up. TRON's post-quantum work is still testnet-only, which leaves NEAR โ live on mainnet since July โ as the one chain that both shipped quantum-safe signing and held green, though even that cannot be pinned to quantum alone. Zcash's earlier 1,120% surge came from privacy demand and a 2025 Robinhood listing, not its undisclosed quantum plan. Readiness, so far, has not paid.
Where to Research and Track Quantum-Resistant Coins on DropsTab
The market isn't pricing readiness yet, so the edge is watching who actually ships โ chain by chain, and as a cohort. DropsTab covers both: each project's supply, category and roadmap sits on its own coin page, while a live Quantum-Resistant Chains custom tab and an equal-weight public portfolio let you follow the whole basket in one view. Research a single name on its DropsTab coin page, track the full quantum-resistant basket, or clone the portfolio and build your own.